[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fK1iaHNjNkgWLXvxy0EXmpnfe_u0vHuzYYg8o8G1MRp8":3,"$fFj7k9jwTNVPdDQmSugjj4RIF852Xj20HpwofuP8jsAU":361,"$fqpx44LS88gM_0WL-F-o3LrWY7Dr8tTS52L66g9k9TAU":365},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":27,"vuln_count":14,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30,"discovery_status":31,"vulnerabilities":32,"developer":59,"crawl_stats":38,"alternatives":62,"analysis":137,"fingerprints":328},"mailercloud-integrate-webforms-synchronize-contacts","Mailercloud – Integrate webforms and synchronize website contacts","1.1.1","mailercloud","https:\u002F\u002Fprofiles.wordpress.org\u002Fmailercloud\u002F","\u003Cp>Enhance your email marketing with Mailercloud’s WordPress plugin. Integrate web forms, synchronize contacts, automate workflows, and create stunning email campaigns. Perfect for businesses of all sizes to grow their audience and engagement.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.mailercloud.com\" rel=\"nofollow ugc\">Mailercloud\u003C\u002Fa> Email Marketing Plugin is the ultimate solution to enhance your email marketing efforts by integrating web forms and synchronizing contacts. This plugin helps you collect subscribers, capture leads through web forms, and trigger automated emails.\u003C\u002Fp>\n\u003Cp>Mailercloud connects the forms you already use on WordPress to your Mailercloud account, so every lead you collect flows straight into your contact lists — ready for email marketing. No third-party bridge plugin required.\u003C\u002Fp>\n\u003Cp>Already running Contact Form 7, WPForms, Elementor, Gravity Forms, Ninja Forms, or Formidable? Map their fields to Mailercloud once, and new submissions are added or updated automatically. Prefer to build a form from scratch? The plugin also ships a Mailercloud signup form block you can drop into any page or post.\u003C\u002Fp>\n\u003Ch3>Key Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Web Form Integration\u003C\u002Fstrong>: Seamlessly integrate custom web forms to capture leads.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Contact Synchronization\u003C\u002Fstrong>: Automatically sync contacts to your Mailercloud account.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Campaigns\u003C\u002Fstrong>: Design and send emails with an intuitive drag-and-drop editor.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.mailercloud.com\u002Ffeatures\u002Fsegmentation\" rel=\"nofollow ugc\">Segmentation\u003C\u002Fa>\u003C\u002Fstrong>: Create targeted email campaigns by segmenting your contacts.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.mailercloud.com\u002Ffeatures\u002Femail-automation\" rel=\"nofollow ugc\">Advanced Automation\u003C\u002Fa>\u003C\u002Fstrong>: Set up workflows to nurture leads and improve engagement.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.mailercloud.com\u002Famp\" rel=\"nofollow ugc\">AMP Email\u003C\u002Fa>\u003C\u002Fstrong>: Send interactive emails for better engagement and conversion.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Analytics\u003C\u002Fstrong>: Access detailed reports to track email performance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GDPR Compliance\u003C\u002Fstrong>: Manage user consent and ensure compliance.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwww.mailercloud.com\u002Fintegrations\u002F\" rel=\"nofollow ugc\">Integration\u003C\u002Fa>\u003C\u002Fstrong>: Connect with popular CRM and eCommerce platforms.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Form plugin connectors (new in 1.1.0)\u003C\u002Fstrong>: Send submissions from Contact Form 7, WPForms, Elementor Forms, Gravity Forms, Ninja Forms and Formidable straight into a Mailercloud list — no third-party bridge needed. Map each form field to a Mailercloud field and optionally apply tags. Visitors are captured by email even without a WordPress account.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Capture analytics (new in 1.1.0)\u003C\u002Fstrong>: See how many leads the plugin has captured, by source, right inside WordPress.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Additional Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Customizable Forms\u003C\u002Fstrong>: Tailor web forms to match your brand’s style.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-language Support\u003C\u002Fstrong>: Manage campaigns in multiple languages.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Responsive Design\u003C\u002Fstrong>: Ensure emails are optimized for all devices.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>A\u002FB Testing\u003C\u002Fstrong>: Optimize emails by testing different versions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Advanced Reporting\u003C\u002Fstrong>: Gain deep insights into campaign performance.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>What the Plugin Does\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Cstrong>Form connectors\u003C\u002Fstrong>: link Contact Form 7, WPForms, Elementor, Gravity Forms, Ninja Forms, and Formidable to Mailercloud lists.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Lead capture from any visitor\u003C\u002Fstrong>: captures contacts from form submissions — not just registered WordPress users — matched on email so records stay clean.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Contact sync\u003C\u002Fstrong>: push your WordPress users to Mailercloud and keep them up to date, in efficient batches even on large sites.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Field mapping\u003C\u002Fstrong>: map form and user fields to Mailercloud contact attributes, and create new attributes from WordPress.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Built-in signup form block\u003C\u002Fstrong>: add a Mailercloud form to any page, post, or widget area.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>List-growth view\u003C\u002Fstrong>: see how many leads your forms are capturing, without leaving WordPress.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>What You Get in Mailercloud\u003C\u002Fh3>\n\u003Cp>Once your contacts are in Mailercloud, the platform handles everything downstream — these run in your Mailercloud account, not inside WordPress:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Drag-and-drop email campaign editor\u003C\u002Fli>\n\u003Cli>Segmentation for targeted sending\u003C\u002Fli>\n\u003Cli>Email automation and workflows\u003C\u002Fli>\n\u003Cli>AMP interactive emails\u003C\u002Fli>\n\u003Cli>A\u002FB testing and detailed analytics\u003C\u002Fli>\n\u003Cli>GDPR consent tools\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>How It Works\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.mailercloud.com\u002F\" rel=\"nofollow ugc\">Mailercloud\u003C\u002Fa> simplifies email marketing by providing a user-friendly interface and powerful features. Capture leads through customizable web forms embedded on your WordPress site, with contacts automatically synchronized to your Mailercloud account. Create stunning email campaigns with the drag-and-drop editor, segment contacts for personalized communication, and automate workflows to maintain consistent engagement. Detailed analytics help you track performance, refine strategies, and achieve better results. GDPR tools ensure your marketing efforts comply with regulations.\u003C\u002Fp>\n\u003Col>\n\u003Cli>Install the plugin and connect it to your Mailercloud account with your API key.\u003C\u002Fli>\n\u003Cli>Pick a form (Contact Form 7, WPForms, Elementor, Gravity Forms, Ninja Forms, Formidable, or the built-in block) and choose the Mailercloud list it should feed.\u003C\u002Fli>\n\u003Cli>Map the form fields to Mailercloud contact attributes.\u003C\u002Fli>\n\u003Cli>Publish. Every submission is added or updated in Mailercloud automatically — then build campaigns and automations in your Mailercloud account.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>More About Mailercloud\u003C\u002Fh3>\n\u003Cp>Since 2018 \u003Ca href=\"https:\u002F\u002Fwww.mailercloud.com\u002F\" rel=\"nofollow ugc\">Mailercloud\u003C\u002Fa> has been a leading email marketing platform helping thousands of businesses, entrepreneurs, and marketers succeed with email marketing. Our mission is to provide powerful and user-friendly tools that enable you to create, send, and optimize email campaigns effectively. Whether you are just starting out or looking to enhance your existing email marketing efforts, Mailercloud offers the features and support you need to grow your audience and achieve your business goals. Get started with a free account today.\u003C\u002Fp>\n\u003Ch3>Useful Links\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fhelp.mailercloud.com\u002Fen\" rel=\"nofollow ugc\">Help center\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.mailercloud.com\u002Fpricing\" rel=\"nofollow ugc\">Pricing\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.mailercloud.com\u002Fintegrations\u002F\" rel=\"nofollow ugc\">integrations\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.mailercloud.com\u002Ffaqs\" rel=\"nofollow ugc\">FAQ\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Connect Contact Form 7, WPForms, Elementor, Gravity, Ninja & Formidable to Mailercloud. Capture leads and sync contacts automatically.",100,4886,80,1,"2026-07-01T05:12:00.000Z","7.0.2","4.0","7.2.5",[20,21,22,23,24],"contact-form-7","elementor-forms","email-marketing","gravity-forms","wpforms","https:\u002F\u002Fapp.mailercloud.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmailercloud-integrate-webforms-synchronize-contacts.1.1.1.zip",99,0,"2026-03-02 00:00:00","2026-07-22T17:31:50.256Z","no_bundle",[33],{"id":34,"url_slug":35,"title":36,"description":37,"plugin_slug":4,"theme_slug":38,"affected_versions":39,"patched_in_version":40,"severity":41,"cvss_score":42,"cvss_vector":43,"vuln_type":44,"published_date":29,"updated_date":45,"references":46,"days_to_patch":48,"patch_diff_files":49,"patch_trac_url":38,"research_status":50,"research_verified":51,"research_rounds_completed":52,"research_plan":53,"research_summary":54,"research_vulnerable_code":38,"research_fix_diff":38,"research_exploit_outline":55,"research_model_used":56,"research_started_at":57,"research_completed_at":58,"research_error":38,"poc_status":38,"poc_video_id":38,"poc_summary":38,"poc_steps":38,"poc_tested_at":38,"poc_wp_version":38,"poc_php_version":38,"poc_playwright_script":38,"poc_exploit_code":38,"poc_has_trace":51,"poc_model_used":38,"poc_verification_depth":38},"CVE-2026-39713","mailercloud-integrate-webforms-and-synchronize-website-contacts-missing-authorization","Mailercloud – Integrate webforms and synchronize website contacts \u003C= 1.0.7 - Missing Authorization","The Mailercloud – Integrate webforms and synchronize website contacts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.",null,"\u003C=1.0.7","1.0.8","medium",5.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Missing Authorization","2026-05-26 18:19:07",[47],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F7728b8d3-5f85-4411-968a-2239c05273d8?source=api-prod",86,[],"researched",false,3,"Since the source code for version 1.0.7 of the **Mailercloud – Integrate webforms and synchronize website contacts** plugin is not provided, this research plan is based on the vulnerability description, CVSS vector (AV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N), and common patterns in WordPress \"Missing Authorization\" vulnerabilities.\n\nThe vulnerability involves an unauthenticated user (PR:N) performing an unauthorized action (Integrity: Low). This typically points to an AJAX handler or an `admin_init`\u002F`init` hook that processes data without a `current_user_can()` check.\n\n### 1. Vulnerability Summary\nThe Mailercloud plugin (up to 1.0.7) fails to implement authorization checks on certain functions accessible via WordPress hooks. Specifically, it likely exposes a functionality intended for administrators—such as updating plugin settings, API keys, or synchronization parameters—to unauthenticated users by registering a `wp_ajax_nopriv_` handler or an `admin_init` handler that lacks capability verification.\n\n### 2. Attack Vector Analysis\n*   **Endpoint:** `http:\u002F\u002F\u003Ctarget>\u002Fwp-admin\u002Fadmin-ajax.php` (for AJAX) or any page (for `admin_init`\u002F`init`).\n*   **Action (Inferred):** Likely related to `mc_save_settings`, `mc_api_key_save`, or `mc_sync_contacts`.\n*   **Method:** HTTP POST request.\n*   **Authentication:** None required (unauthenticated).\n*   **Preconditions:** The plugin must be active.\n\n### 3. Code Flow (Inferred)\n1.  The plugin registers an action via `add_action( 'wp_ajax_nopriv_[action_name]', 'function_name' )` or `add_action( 'admin_init', 'function_name' )`.\n2.  The `function_name` callback is triggered.\n3.  The callback processes user-supplied data from `$_POST` or `$_GET`.\n4.  **Security Failure:** The function performs sensitive operations (e.g., `update_option()`) without calling `current_user_can( 'manage_options' )`.\n5.  **Security Failure:** The function may also lack a nonce check (`check_ajax_referer` or `wp_verify_nonce`).\n\n### 4. Nonce Acquisition Strategy\nIf the vulnerable function uses `check_ajax_referer` or `check_admin_referer` but lacks authorization, a nonce must be obtained.\n\n1.  **Search for Nonce Creation:** Search for `wp_create_nonce` in the plugin code to identify where the nonce is generated.\n2.  **Locate Localized Scripts:** Look for `wp_localize_script` to see if the nonce is passed to the frontend.\n3.  **Shortcode Identification:** Identify any shortcodes (e.g., `[mailercloud_form]`) that might enqueue the script containing the nonce.\n4.  **Creation & Navigation:**\n    *   Create a test page: `wp post create --post_type=page --post_status=publish --post_content='[SHORTCODE_FOUND]'`.\n    *   Navigate to the page using `browser_navigate`.\n    *   Extract the nonce using `browser_eval`: `browser_eval(\"window.mc_ajax_obj?.nonce\")` (Replace `mc_ajax_obj` and `nonce` with the actual keys found in the source).\n\n*Note: If the vulnerability is a total lack of security, no nonce will be required.*\n\n### 5. Exploitation Strategy\nThe agent should follow these steps to identify and exploit the specific sink:\n\n#### Step 1: Discovery\nSearch the plugin directory for vulnerable registration patterns:\n```bash\ngrep -rn \"wp_ajax_nopriv_\" .\ngrep -rn \"admin_init\" .\n```\nFor each identified function, check for `current_user_can`. The function that lacks this check and performs an `update_option` or `wpdb->query` is the target.\n\n#### Step 2: Target Identification (Example)\nAssume the found action is `mc_save_api_key`.\n*   **Vulnerable File:** `includes\u002Fclass-mailercloud-settings.php` (Example)\n*   **Vulnerable Function:** `save_settings` (Example)\n*   **Parameters:** `api_key`, `list_id`.\n\n#### Step 3: Execution (Unauthenticated Setting Update)\nIf the vulnerability allows updating the API key, the exploit would look like this:\n\n**HTTP Request:**\n```http\nPOST \u002Fwp-admin\u002Fadmin-ajax.php HTTP\u002F1.1\nHost: \u003Ctarget>\nContent-Type: application\u002Fx-www-form-urlencoded\n\naction=mc_save_api_key&api_key=pwned_key_1337&nonce=[EXTRACTED_NONCE]\n```\n\n### 6. Test Data Setup\n1.  Install and activate the plugin.\n2.  (Optional) Set a valid-looking API key via WP-CLI to provide a baseline: `wp option update mailercloud_api_key \"original_key_12345\"`.\n3.  If the plugin requires a form to be present for nonce generation, identify the shortcode via `grep -r \"add_shortcode\" .`.\n\n### 7. Expected Results\n*   The server returns a `200 OK` or a JSON success message (e.g., `{\"success\":true}`).\n*   The targeted setting (e.g., `mailercloud_api_key`) is modified in the database despite the request being unauthenticated.\n\n### 8. Verification Steps\nAfter sending the exploit request, verify the state change using WP-CLI:\n```bash\n# Verify if the option was changed\nwp option get mailercloud_api_key\n```\nA successful exploit will show the value `pwned_key_1337`.\n\n### 9. Alternative Approaches\n*   **admin_init Bypass:** If the function is hooked to `admin_init`, it can often be triggered by any request to `\u002Fwp-admin\u002Fadmin-post.php` or even the frontend if the plugin doesn't restrict `admin_init` to the dashboard context.\n*   **Sync Trigger:** If setting updates are not possible, check for actions like `mc_sync_contacts` which might allow an attacker to trigger resource-intensive synchronization processes, leading to potential Denial of Service (DoS) or unauthorized data transmission to a third-party API.\n*   **Field Mapping Manipulation:** Look for actions that save \"field mappings.\" An attacker might change these to redirect user-submitted form data to incorrect Mailercloud attributes.","The Mailercloud – Integrate webforms and synchronize website contacts plugin for WordPress is vulnerable to unauthorized access in versions up to and including 1.0.7. This vulnerability stems from missing capability checks on sensitive functions, enabling unauthenticated attackers to perform unauthorized actions such as updating plugin configurations.","1. Identify a vulnerable AJAX action (e.g., one registered with `wp_ajax_nopriv_`) or an `admin_init` hook that lacks a `current_user_can()` check.\n2. Access a public page or post containing the plugin's shortcode to extract any required nonces from the localized JavaScript objects.\n3. Construct a POST request to `\u002Fwp-admin\u002Fadmin-ajax.php` containing the `action` parameter and the specific settings to be modified (e.g., API keys).\n4. Execute the request unauthenticated to overwrite the plugin's options in the database.","gemini-3-flash-preview","2026-04-18 22:05:57","2026-04-18 22:06:17",{"slug":7,"display_name":7,"profile_url":8,"plugin_count":14,"total_installs":11,"avg_security_score":27,"avg_patch_time_days":48,"trust_score":60,"computed_at":61},87,"2026-08-26T12:00:36.713Z",[63,80,97,109,121],{"slug":64,"name":65,"version":66,"author":67,"author_profile":68,"description":69,"short_description":70,"active_installs":71,"downloaded":72,"rating":28,"num_ratings":28,"last_updated":73,"tested_up_to":16,"requires_at_least":74,"requires_php":75,"tags":76,"homepage":78,"download_link":79,"security_score":11,"vuln_count":28,"unpatched_count":28,"last_vuln_date":38,"fetched_at":30},"integrate-with-hubspot-crm","Integration for HubSpot – Contact Form 7, WPForms, Elementor, Gravity Forms and More","1.0.16","Plugcrux","https:\u002F\u002Fprofiles.wordpress.org\u002Fplugcrux\u002F","\u003Cp>This plugin sends form submissions from Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and Formidable Forms to HubSpot CRM.\u003C\u002Fp>\n\u003Cp>When a user submits a form, the plugin can create or update records—such as contacts, companies, or deals—in your HubSpot CRM account. This helps reduce manual data entry and keeps your HubSpot data in sync with your website forms.\u003C\u002Fp>\n\u003Cp>Supported form plugins:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcontact-form-7\u002F\" rel=\"ugc\">Contact Form 7\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwpforms-lite\u002F\" rel=\"ugc\">WPForms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Felementor\u002F\" rel=\"ugc\">Elementor Forms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.gravityforms.com\u002F\" rel=\"nofollow ugc\">Gravity Forms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fformidable\u002F\" rel=\"ugc\">Formidable Forms\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FxHMIQjzV6z4?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch3>Authentication\u003C\u002Fh3>\n\u003Cp>To connect your HubSpot CRM account:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to the Accounts page in the plugin.\u003C\u002Fli>\n\u003Cli>Click Add Account.\u003C\u002Fli>\n\u003Cli>Enter an identifiable account name (for example, “Main HubSpot CRM Account”).\u003C\u002Fli>\n\u003Cli>Click Authenticate to open the HubSpot authorization page.\u003C\u002Fli>\n\u003Cli>Log in to HubSpot and approve the requested permissions.\u003C\u002Fli>\n\u003Cli>After approval, you will be redirected back to WordPress, and the account will be listed on the Accounts page.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Add Integration\u003C\u002Fh3>\n\u003Cp>To create a new integration:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to the Setup page.\u003C\u002Fli>\n\u003Cli>Click Add Integration.\u003C\u002Fli>\n\u003Cli>Enter an integration name (for example, “Lead Capture Form”).\u003C\u002Fli>\n\u003Cli>Select the form type (Contact Form 7, WPForms, Elementor, Gravity Forms, or Formidable).\u003C\u002Fli>\n\u003Cli>Choose the connected HubSpot CRM account.\u003C\u002Fli>\n\u003Cli>Select the HubSpot object where records should be created or updated (for example, Contacts, Companies, Deals).\u003C\u002Fli>\n\u003Cli>Map form fields to HubSpot CRM fields in the field mapping section.\u003C\u002Fli>\n\u003Cli>Optionally map additional fields such as phone, company, custom properties, or attachments (where supported).\u003C\u002Fli>\n\u003Cli>Use the filter criteria section to apply conditions (for example, sync only if a specific checkbox is selected).\u003C\u002Fli>\n\u003Cli>Click Save Mapping.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Logs\u003C\u002Fh3>\n\u003Cp>The plugin provides a logs section to review how data is being sent to HubSpot CRM.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Open the Logs page to see a list of submissions and their statuses.\u003C\u002Fli>\n\u003Cli>Typical statuses include:\n\u003Cul>\n\u003Cli>SUCCESS – record created or updated successfully.\u003C\u002Fli>\n\u003Cli>RECORD_FAILED – record not created due to an error (for example, a required field is missing).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Additional options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Filter logs by integration, status, or date range.\u003C\u002Fli>\n\u003Cli>Open the log details view to see the full request, response, and error messages.\u003C\u002Fli>\n\u003Cli>Resync or delete individual records, or use bulk actions where available.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Settings\u003C\u002Fh3>\n\u003Cp>Global settings can be managed from the Settings page:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Delete data on uninstall – when enabled, plugin data will be removed when the plugin is deleted from WordPress.\u003C\u002Fli>\n\u003Cli>Error email notification – enable or disable email notifications when a record fails.\u003C\u002Fli>\n\u003Cli>Notification emails – specify one or more email addresses (comma-separated) to receive error notifications.\u003C\u002Fli>\n\u003Cli>Email subject – set the subject line for error notification emails.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy and Data Handling\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Form submission data is sent from your WordPress site to HubSpot CRM via their API.\u003C\u002Fli>\n\u003Cli>The plugin does not send data to any third-party service other than the configured HubSpot services.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Free and Paid Features\u003C\u002Fh3>\n\u003Cp>The plugin is available in a free version with optional paid features.\u003C\u002Fp>\n\u003Cp>Free version includes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Connect up to 2 HubSpot CRM accounts\u003C\u002Fli>\n\u003Cli>Connect up to 2 forms\u003C\u002Fli>\n\u003Cli>Support for standard fields and basic field mapping\u003C\u002Fli>\n\u003Cli>Custom value support\u003C\u002Fli>\n\u003Cli>System fields mapping (where supported)\u003C\u002Fli>\n\u003Cli>Note field integration\u003C\u002Fli>\n\u003Cli>Error log view and basic resync options\u003C\u002Fli>\n\u003Cli>Email notifications for failed records\u003C\u002Fli>\n\u003Cli>No daily record limit enforced by the plugin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Paid version adds:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Unlimited account connections (subject to HubSpot limits)\u003C\u002Fli>\n\u003Cli>Unlimited form connections\u003C\u002Fli>\n\u003Cli>Premium field support\u003C\u002Fli>\n\u003Cli>Custom field mapping\u003C\u002Fli>\n\u003Cli>Extended resync options and log handling\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Upgrade now: https:\u002F\u002Fintegrazo.com\u002Fproducts\u002Fintegrate-with-hubspot-crm\u003C\u002Fp>\n\u003Ch3>Features Overview\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Connect HubSpot CRM to supported form plugins\u003C\u002Fli>\n\u003Cli>Configure multiple HubSpot accounts and objects\u003C\u002Fli>\n\u003Cli>Map form fields to HubSpot CRM fields, including custom properties\u003C\u002Fli>\n\u003Cli>Real-time syncing of form submissions\u003C\u002Fli>\n\u003Cli>Optional conditional logic to control when records are created or updated\u003C\u002Fli>\n\u003Cli>Activity logs with status and error details\u003C\u002Fli>\n\u003Cli>Resync options for failed records\u003C\u002Fli>\n\u003Cli>Optional email notifications for errors\u003C\u002Fli>\n\u003Cli>Settings to control data removal on uninstall\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>If you need help or want to request a feature:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>https:\u002F\u002Fintegrazo.com\u002Fpages\u002Fcontact  \u003C\u002Fli>\n\u003Cli>https:\u002F\u002Fintegrazo.com\u002Fpages\u002Frequest-feature  \u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Website: https:\u002F\u002Fintegrazo.com\u003Cbr \u002F>\nEmail: support@integrazo.com\u003C\u002Fp>\n\u003Ch3>Additional Notes\u003C\u002Fh3>\n\u003Cp>This plugin supports WordPress multisite installations and has been tested for compatibility with recent WordPress versions.\u003C\u002Fp>\n","Connect Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and more form submissions with HubSpot CRM.",10,1804,"2026-07-13T05:23:00.000Z","6.0","7.0",[20,21,23,77,24],"hubspot-crm","https:\u002F\u002Fintegrazo.com\u002Fproducts\u002Fintegrate-with-hubspot-crm","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fintegrate-with-hubspot-crm.1.0.16.zip",{"slug":81,"name":82,"version":83,"author":67,"author_profile":68,"description":84,"short_description":85,"active_installs":71,"downloaded":86,"rating":87,"num_ratings":88,"last_updated":89,"tested_up_to":90,"requires_at_least":74,"requires_php":91,"tags":92,"homepage":94,"download_link":95,"security_score":11,"vuln_count":28,"unpatched_count":28,"last_vuln_date":38,"fetched_at":96},"integrate-with-mailchimp","Integration for Mailchimp – Contact Form 7, WPForms, Elementor, Gravity Forms and More","1.0.11","\u003Cp>This plugin sends form submissions from Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and Formidable Forms to Mailchimp.\u003C\u002Fp>\n\u003Cp>When a user submits a form, the plugin can add or update subscribers in your Mailchimp audience. This helps reduce manual data entry and keeps your Mailchimp lists in sync with your website forms.\u003C\u002Fp>\n\u003Cp>Supported form plugins:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcontact-form-7\u002F\" rel=\"ugc\">Contact Form 7\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwpforms-lite\u002F\" rel=\"ugc\">WPForms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Felementor\u002F\" rel=\"ugc\">Elementor Forms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.gravityforms.com\u002F\" rel=\"nofollow ugc\">Gravity Forms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fformidable\u002F\" rel=\"ugc\">Formidable Forms\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002Fi4_GFZFVo84?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch3>Authentication\u003C\u002Fh3>\n\u003Cp>To connect your Mailchimp account:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to the Accounts page in the plugin.\u003C\u002Fli>\n\u003Cli>Click Add Account.\u003C\u002Fli>\n\u003Cli>Enter an identifiable account name (for example, “Main Mailchimp Account”).\u003C\u002Fli>\n\u003Cli>Enter your Mailchimp API key in the API Key field.\u003C\u002Fli>\n\u003Cli>Click Save Account.\u003C\u002Fli>\n\u003Cli>After saving, the account will be listed on the Accounts page.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Add Integration\u003C\u002Fh3>\n\u003Cp>To create a new integration:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to the Setup page.\u003C\u002Fli>\n\u003Cli>Click Add Integration.\u003C\u002Fli>\n\u003Cli>Enter an integration name (for example, “Newsletter Signup Form”).\u003C\u002Fli>\n\u003Cli>Select the form type (Contact Form 7, WPForms, Elementor, Gravity Forms, or Formidable).\u003C\u002Fli>\n\u003Cli>Choose the connected Mailchimp account.\u003C\u002Fli>\n\u003Cli>Select the Mailchimp audience (list) where subscribers should be added.\u003C\u002Fli>\n\u003Cli>Map form fields to Mailchimp fields in the field mapping section.\u003C\u002Fli>\n\u003Cli>Optionally map additional fields such as name, phone, address, or tags (where supported).\u003C\u002Fli>\n\u003Cli>Use the filter criteria section to apply conditions (for example, sync only if a checkbox is selected).\u003C\u002Fli>\n\u003Cli>Click Save Mapping.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Logs\u003C\u002Fh3>\n\u003Cp>The plugin provides a logs section to review how data is being sent to Mailchimp.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Open the Logs page to see a list of submissions and their statuses.\u003C\u002Fli>\n\u003Cli>Typical statuses include:\n\u003Cul>\n\u003Cli>SUCCESS – subscriber created or updated successfully.\u003C\u002Fli>\n\u003Cli>RECORD_FAILED – subscriber not created due to an error (for example, an invalid email).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Additional options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Filter logs by integration, status, or date range.\u003C\u002Fli>\n\u003Cli>Open the log details view to see the full request, response, and error messages.\u003C\u002Fli>\n\u003Cli>Resync or delete individual records, or use bulk actions where available.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Settings\u003C\u002Fh3>\n\u003Cp>Global settings can be managed from the Settings page:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Delete data on uninstall – when enabled, plugin data will be removed when the plugin is deleted from WordPress.\u003C\u002Fli>\n\u003Cli>Error email notification – enable or disable email notifications when a record fails.\u003C\u002Fli>\n\u003Cli>Notification emails – specify one or more email addresses (comma-separated) to receive error notifications.\u003C\u002Fli>\n\u003Cli>Email subject – set the subject line for error notification emails.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy and Data Handling\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Form submission data is sent from your WordPress site to Mailchimp via their API.\u003C\u002Fli>\n\u003Cli>The plugin does not send data to any third-party service other than the configured Mailchimp services.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Free and Paid Features\u003C\u002Fh3>\n\u003Cp>The plugin is available in a free version with optional paid features.\u003C\u002Fp>\n\u003Cp>Free version includes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Connect up to 2 Mailchimp accounts\u003C\u002Fli>\n\u003Cli>Connect up to 2 forms\u003C\u002Fli>\n\u003Cli>Support for standard fields and basic field mapping\u003C\u002Fli>\n\u003Cli>Custom value support\u003C\u002Fli>\n\u003Cli>System fields mapping (where supported)\u003C\u002Fli>\n\u003Cli>Error log view and basic management\u003C\u002Fli>\n\u003Cli>Email notifications for failed records\u003C\u002Fli>\n\u003Cli>No daily record limit enforced by the plugin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Paid version adds:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Unlimited account connections (subject to Mailchimp limits)\u003C\u002Fli>\n\u003Cli>Unlimited form connections\u003C\u002Fli>\n\u003Cli>Premium field support\u003C\u002Fli>\n\u003Cli>Custom field mapping\u003C\u002Fli>\n\u003Cli>Extended resync options and log handling\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Upgrade now: https:\u002F\u002Fintegrazo.com\u002Fproducts\u002Fintegrate-with-mailchimp\u003C\u002Fp>\n\u003Ch3>Features Overview\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Connect Mailchimp to supported form plugins\u003C\u002Fli>\n\u003Cli>Configure multiple Mailchimp accounts and audiences\u003C\u002Fli>\n\u003Cli>Map form fields to Mailchimp fields, including custom merge fields\u003C\u002Fli>\n\u003Cli>Real-time syncing of form submissions to Mailchimp\u003C\u002Fli>\n\u003Cli>Optional conditional logic to control when subscribers are added or updated\u003C\u002Fli>\n\u003Cli>Activity logs with status and error details\u003C\u002Fli>\n\u003Cli>Resync options for failed records\u003C\u002Fli>\n\u003Cli>Optional email notifications for errors\u003C\u002Fli>\n\u003Cli>Settings to control data removal on uninstall\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>If you need help or want to request a feature:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>https:\u002F\u002Fintegrazo.com\u002Fpages\u002Fcontact  \u003C\u002Fli>\n\u003Cli>https:\u002F\u002Fintegrazo.com\u002Fpages\u002Frequest-feature  \u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Website: https:\u002F\u002Fintegrazo.com\u003Cbr \u002F>\nEmail: support@integrazo.com\u003C\u002Fp>\n\u003Ch3>Additional Notes\u003C\u002Fh3>\n\u003Cp>This plugin supports WordPress multisite installations and has been tested for compatibility with recent WordPress versions.\u003C\u002Fp>\n","Connect Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and more form submissions with Mailchimp.",1176,96,4,"2026-03-10T11:01:00.000Z","6.9.4","7.4",[20,21,23,93,24],"mailchimp","https:\u002F\u002Fintegrazo.com\u002Fproducts\u002Fintegrate-with-mailchimp","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fintegrate-with-mailchimp.1.0.11.zip","2026-04-16T10:56:18.058Z",{"slug":98,"name":99,"version":100,"author":67,"author_profile":68,"description":101,"short_description":102,"active_installs":71,"downloaded":103,"rating":28,"num_ratings":28,"last_updated":104,"tested_up_to":16,"requires_at_least":74,"requires_php":75,"tags":105,"homepage":107,"download_link":108,"security_score":11,"vuln_count":28,"unpatched_count":28,"last_vuln_date":38,"fetched_at":30},"integrate-with-zoho-campaigns","Integration for Zoho Campaigns – Contact Form 7, WPForms, Elementor, Gravity Forms and More","1.0.13","\u003Cp>This plugin sends form submissions from Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and Formidable Forms to Zoho Campaigns.\u003C\u002Fp>\n\u003Cp>When a user submits a form, the plugin can create or update subscribers in your Zoho Campaigns mailing lists. This helps reduce manual data entry and keeps your Zoho Campaigns lists in sync with your website forms.\u003C\u002Fp>\n\u003Cp>Supported form plugins:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcontact-form-7\u002F\" rel=\"ugc\">Contact Form 7\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwpforms-lite\u002F\" rel=\"ugc\">WPForms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Felementor\u002F\" rel=\"ugc\">Elementor Forms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.gravityforms.com\u002F\" rel=\"nofollow ugc\">Gravity Forms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fformidable\u002F\" rel=\"ugc\">Formidable Forms\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Video tutorial:\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FM5MKPvSrpD0?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch3>Authentication\u003C\u002Fh3>\n\u003Cp>To connect your Zoho Campaigns account:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to the Accounts page in the plugin.\u003C\u002Fli>\n\u003Cli>Click Add Account.\u003C\u002Fli>\n\u003Cli>Enter an identifiable account name (for example, “Main Zoho Campaigns Account”).\u003C\u002Fli>\n\u003Cli>Select the appropriate data center (for example, \u003Ccode>zoho.com\u003C\u002Fcode>, \u003Ccode>zoho.eu\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>Click Authenticate to open the Zoho authorization page.\u003C\u002Fli>\n\u003Cli>Log in to Zoho and approve the requested permissions.\u003C\u002Fli>\n\u003Cli>After approval, you will be redirected back to WordPress, and the account will be listed on the Accounts page.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Add Integration\u003C\u002Fh3>\n\u003Cp>To create a new integration:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to the Setup page.\u003C\u002Fli>\n\u003Cli>Click Add Integration.\u003C\u002Fli>\n\u003Cli>Enter an integration name (for example, “Newsletter Signup”).\u003C\u002Fli>\n\u003Cli>Select the form type (Contact Form 7, WPForms, Elementor, Gravity Forms, or Formidable).\u003C\u002Fli>\n\u003Cli>Choose the connected Zoho Campaigns account.\u003C\u002Fli>\n\u003Cli>Select the Zoho Campaigns list where subscribers should be added.\u003C\u002Fli>\n\u003Cli>Map form fields to Zoho Campaigns fields in the field mapping section.\u003C\u002Fli>\n\u003Cli>Optionally map additional fields such as custom fields, country, city, UTM parameters, or submitted URLs (where supported).\u003C\u002Fli>\n\u003Cli>Use the filter criteria section to apply conditions (for example, sync only if a checkbox is selected).\u003C\u002Fli>\n\u003Cli>Click Save Mapping.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Logs\u003C\u002Fh3>\n\u003Cp>The plugin provides a logs section to review how data is being sent to Zoho Campaigns.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Open the Logs page to see a list of submissions and their statuses.\u003C\u002Fli>\n\u003Cli>Typical statuses include:\n\u003Cul>\n\u003Cli>SUCCESS – record synced successfully.\u003C\u002Fli>\n\u003Cli>RECORD_FAILED – record not synced due to an error (for example, an invalid email).\u003C\u002Fli>\n\u003Cli>AI_DETECTION – record held due to AI rules (for example, based on domain rules).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Additional options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Filter logs by integration, status, or date range.\u003C\u002Fli>\n\u003Cli>Open the log details view to see the full request, response, and error messages.\u003C\u002Fli>\n\u003Cli>Resync or delete individual records, or use bulk actions where available.\u003C\u002Fli>\n\u003Cli>Review AI-detected records and resync them after manual review, if required.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Settings\u003C\u002Fh3>\n\u003Cp>Global settings can be managed from the Settings page:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Delete data on uninstall – when enabled, plugin data will be removed when the plugin is deleted from WordPress.\u003C\u002Fli>\n\u003Cli>Error email notification – enable or disable email notifications when a record fails.\u003C\u002Fli>\n\u003Cli>Notification emails – specify one or more email addresses (comma-separated) to receive error notifications.\u003C\u002Fli>\n\u003Cli>Email subject – set the subject line for error notification emails.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Form Filters\u003C\u002Fh3>\n\u003Cp>Form filter options can be managed from the Form Filters section:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Email validation – configure rules to handle email addresses from specific domains (for example, public email domains).\u003C\u002Fli>\n\u003Cli>Blocked domains – add or remove domains that should be treated according to your rules.\u003C\u002Fli>\n\u003Cli>Action for blocked emails:\n\u003Cul>\n\u003Cli>Send to Zoho Campaigns (ignore AI detection), or\u003C\u002Fli>\n\u003Cli>Store in logs for review and manual resync later.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Tabs for Email Validation, Email Detection, and Spam Detection – configure rules separately for each type of check.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Note: If Double Opt-in is enabled in Zoho Campaigns, subscribers will receive a confirmation email and will be added to the list only after confirmation. This behavior can be adjusted in Zoho Campaigns settings.\u003C\u002Fp>\n\u003Ch3>Privacy and Data Handling\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Form submission data is sent from your WordPress site to Zoho Campaigns via their API.\u003C\u002Fli>\n\u003Cli>The plugin does not send data to any third-party service other than the configured Zoho services.\u003C\u002Fli>\n\u003Cli>Data handling is subject to your Zoho Campaigns account configuration and policies.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Free and Paid Features\u003C\u002Fh3>\n\u003Cp>The plugin is available in a free version with optional paid features.\u003C\u002Fp>\n\u003Cp>Free version includes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Connect up to 2 Zoho Campaigns accounts\u003C\u002Fli>\n\u003Cli>Connect up to 2 forms\u003C\u002Fli>\n\u003Cli>Support for standard fields and basic field mapping\u003C\u002Fli>\n\u003Cli>Custom value support\u003C\u002Fli>\n\u003Cli>Basic AI settings for email handling\u003C\u002Fli>\n\u003Cli>System fields mapping where applicable\u003C\u002Fli>\n\u003Cli>Error log view and basic management\u003C\u002Fli>\n\u003Cli>No daily record limit enforced by the plugin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Paid version adds:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Unlimited account connections (subject to Zoho limits)\u003C\u002Fli>\n\u003Cli>Unlimited form connections\u003C\u002Fli>\n\u003Cli>Premium field support\u003C\u002Fli>\n\u003Cli>Custom field mapping\u003C\u002Fli>\n\u003Cli>Advanced AI options and additional controls\u003C\u002Fli>\n\u003Cli>Extended resync options and log handling\u003C\u002Fli>\n\u003Cli>Email notifications for failed records\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Upgrade now: https:\u002F\u002Fintegrazo.com\u002Fproducts\u002Fintegrate-with-zoho-campaigns\u003C\u002Fp>\n\u003Ch3>Features Overview\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Connect Zoho Campaigns to supported form plugins\u003C\u002Fli>\n\u003Cli>Configure multiple Zoho Campaigns accounts and lists\u003C\u002Fli>\n\u003Cli>Map form fields to Zoho Campaigns fields, including custom fields\u003C\u002Fli>\n\u003Cli>Real-time syncing of form submissions to Zoho Campaigns\u003C\u002Fli>\n\u003Cli>Optional conditional logic to control when records are created or updated\u003C\u002Fli>\n\u003Cli>Activity logs with status and error details\u003C\u002Fli>\n\u003Cli>Resync options for failed or AI-held records\u003C\u002Fli>\n\u003Cli>AI-based rules for email and spam handling\u003C\u002Fli>\n\u003Cli>Optional email notifications for errors\u003C\u002Fli>\n\u003Cli>Settings to control data removal on uninstall\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>If you need help or want to request a feature:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>https:\u002F\u002Fintegrazo.com\u002Fpages\u002Fcontact  \u003C\u002Fli>\n\u003Cli>https:\u002F\u002Fintegrazo.com\u002Fpages\u002Frequest-feature  \u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Website: https:\u002F\u002Fintegrazo.com\u002F\u003Cbr \u002F>\nEmail: support@integrazo.com\u003C\u002Fp>\n\u003Ch3>Additional Notes\u003C\u002Fh3>\n\u003Cp>This plugin supports WordPress multisite installations and has been tested for compatibility with recent WordPress versions.\u003C\u002Fp>\n","Connect Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and more form submissions with Zoho Campaigns.",1428,"2026-07-13T04:48:00.000Z",[20,21,23,24,106],"zoho-campaigns","https:\u002F\u002Fintegrazo.com\u002Fproducts\u002Fintegrate-with-zoho-campaigns","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fintegrate-with-zoho-campaigns.1.0.13.zip",{"slug":110,"name":111,"version":112,"author":67,"author_profile":68,"description":113,"short_description":114,"active_installs":71,"downloaded":115,"rating":28,"num_ratings":28,"last_updated":116,"tested_up_to":16,"requires_at_least":74,"requires_php":75,"tags":117,"homepage":119,"download_link":120,"security_score":11,"vuln_count":28,"unpatched_count":28,"last_vuln_date":38,"fetched_at":30},"integrate-with-zoho-desk","Integration for Zoho Desk – Contact Form 7, WPForms, Elementor, Gravity Forms and More","1.0.14","\u003Cp>This plugin sends form submissions from Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and Formidable Forms to Zoho Desk.\u003C\u002Fp>\n\u003Cp>When a user submits a form, the plugin can create support tickets in your Zoho Desk account. This helps reduce manual ticket creation and keeps your support system synchronized with your website forms.\u003C\u002Fp>\n\u003Cp>Supported form plugins:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fcontact-form-7\u002F\" rel=\"ugc\">Contact Form 7\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwpforms-lite\u002F\" rel=\"ugc\">WPForms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Felementor\u002F\" rel=\"ugc\">Elementor Forms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.gravityforms.com\u002F\" rel=\"nofollow ugc\">Gravity Forms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fformidable\u002F\" rel=\"ugc\">Formidable Forms\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FM15Mvdj2M2E?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch3>Authentication\u003C\u002Fh3>\n\u003Cp>To connect your Zoho Desk account:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to the Accounts page in the plugin.\u003C\u002Fli>\n\u003Cli>Click Add Account.\u003C\u002Fli>\n\u003Cli>Enter an identifiable account name (for example, “Main Zoho Desk Account”).\u003C\u002Fli>\n\u003Cli>Select the appropriate data center (for example, \u003Ccode>zoho.com\u003C\u002Fcode>, \u003Ccode>zoho.eu\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>Click Authenticate to open the Zoho authorization page.\u003C\u002Fli>\n\u003Cli>Log in to Zoho and approve the requested permissions.\u003C\u002Fli>\n\u003Cli>After approval, you will be redirected back to WordPress, and the account will be listed on the Accounts page.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Add Integration\u003C\u002Fh3>\n\u003Cp>To create a new integration:\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to the Setup page.\u003C\u002Fli>\n\u003Cli>Click Add Integration.\u003C\u002Fli>\n\u003Cli>Enter an integration name (for example, “Support Ticket Form”).\u003C\u002Fli>\n\u003Cli>Select the form type (Contact Form 7, WPForms, Elementor, Gravity Forms, or Formidable).\u003C\u002Fli>\n\u003Cli>Choose the connected Zoho Desk account.\u003C\u002Fli>\n\u003Cli>Select the Zoho Desk department where tickets should be created.\u003C\u002Fli>\n\u003Cli>Map form fields to Zoho Desk fields in the field mapping section.\u003C\u002Fli>\n\u003Cli>Optionally map additional fields such as priority, category, custom fields, or attachments (where supported).\u003C\u002Fli>\n\u003Cli>Use the filter criteria section to apply conditions (for example, create tickets only when specific conditions are met).\u003C\u002Fli>\n\u003Cli>Click Save Mapping.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Logs\u003C\u002Fh3>\n\u003Cp>The plugin provides a logs section to review how data is being sent to Zoho Desk.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Open the Logs page to see a list of submissions and their statuses.\u003C\u002Fli>\n\u003Cli>Typical statuses include:\n\u003Cul>\n\u003Cli>SUCCESS – ticket created successfully.\u003C\u002Fli>\n\u003Cli>RECORD_FAILED – ticket not created due to an error.\u003C\u002Fli>\n\u003Cli>AI_DETECTION – held due to AI rules (for example, domain or validation rules).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Additional options:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Filter logs by integration, status, or date range.\u003C\u002Fli>\n\u003Cli>Open the log details view to see the full request, response, and error messages.\u003C\u002Fli>\n\u003Cli>Resync or delete individual records, or use bulk actions where available.\u003C\u002Fli>\n\u003Cli>Review AI-detected records and resync them after manual review, if required.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Settings\u003C\u002Fh3>\n\u003Cp>Global settings can be managed from the Settings page:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Delete data on uninstall – when enabled, plugin data will be removed when the plugin is deleted from WordPress.\u003C\u002Fli>\n\u003Cli>Error email notification – enable or disable email notifications when a record fails.\u003C\u002Fli>\n\u003Cli>Notification emails – specify one or more email addresses (comma-separated) to receive error notifications.\u003C\u002Fli>\n\u003Cli>Email subject – set the subject line for error notification emails.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Form Filters\u003C\u002Fh3>\n\u003Cp>Form filter options can be managed from the Form Filters section:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Email validation – configure rules to handle email addresses from specific domains.\u003C\u002Fli>\n\u003Cli>Blocked domains – add or remove domains that should be treated according to your rules.\u003C\u002Fli>\n\u003Cli>Action for blocked emails:\n\u003Cul>\n\u003Cli>Send to Zoho Desk (ignore AI detection), or\u003C\u002Fli>\n\u003Cli>Store in logs for review and manual resync later.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Tabs for Email Validation, Email Detection, and Spam Detection – configure rules separately for each type of check.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Privacy and Data Handling\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Form submission data is sent from your WordPress site to Zoho Desk via their API.\u003C\u002Fli>\n\u003Cli>The plugin does not send data to any third-party service other than the configured Zoho services.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Free and Paid Features\u003C\u002Fh3>\n\u003Cp>Free version includes:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Connect up to 2 Zoho Desk accounts\u003C\u002Fli>\n\u003Cli>Connect up to 2 forms\u003C\u002Fli>\n\u003Cli>Support for standard fields and basic field mapping\u003C\u002Fli>\n\u003Cli>Custom value support\u003C\u002Fli>\n\u003Cli>System fields mapping (where available)\u003C\u002Fli>\n\u003Cli>Basic AI options\u003C\u002Fli>\n\u003Cli>Error log view and basic management\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Paid version adds:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Unlimited account connections (subject to Zoho limits)\u003C\u002Fli>\n\u003Cli>Unlimited form connections\u003C\u002Fli>\n\u003Cli>Premium field support\u003C\u002Fli>\n\u003Cli>Custom field mapping\u003C\u002Fli>\n\u003Cli>Extended AI controls and detection rules\u003C\u002Fli>\n\u003Cli>Advanced resync options and log handling\u003C\u002Fli>\n\u003Cli>Email notifications for failed records\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Upgrade now: https:\u002F\u002Fintegrazo.com\u002Fproducts\u002Fintegrate-with-zoho-desk\u003C\u002Fp>\n\u003Ch3>Features Overview\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Connect Zoho Desk to supported form plugins\u003C\u002Fli>\n\u003Cli>Configure multiple Zoho Desk accounts and departments\u003C\u002Fli>\n\u003Cli>Map form fields to Zoho Desk fields, including custom fields\u003C\u002Fli>\n\u003Cli>Real-time ticket creation\u003C\u002Fli>\n\u003Cli>Optional conditional logic\u003C\u002Fli>\n\u003Cli>Activity logs with status and error details\u003C\u002Fli>\n\u003Cli>Resync options for failed or AI-held records\u003C\u002Fli>\n\u003Cli>AI-based email and spam handling\u003C\u002Fli>\n\u003Cli>Optional email notifications\u003C\u002Fli>\n\u003Cli>Settings to control data removal on uninstall\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>If you need help or want to request a feature:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>https:\u002F\u002Fintegrazo.com\u002Fpages\u002Fcontact  \u003C\u002Fli>\n\u003Cli>https:\u002F\u002Fintegrazo.com\u002Fpages\u002Frequest-feature  \u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Website: https:\u002F\u002Fintegrazo.com\u003Cbr \u002F>\nEmail: support@integrazo.com\u003C\u002Fp>\n\u003Ch3>Additional Notes\u003C\u002Fh3>\n\u003Cp>This plugin supports WordPress multisite installations and has been tested for compatibility with recent WordPress versions.\u003C\u002Fp>\n","Connect Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and more form submissions with Zoho Desk.",1342,"2026-07-13T04:56:00.000Z",[20,21,23,24,118],"zoho-desk","https:\u002F\u002Fintegrazo.com\u002Fproducts\u002Fintegrate-with-zoho-desk","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fintegrate-with-zoho-desk.1.0.14.zip",{"slug":122,"name":123,"version":124,"author":125,"author_profile":126,"description":127,"short_description":128,"active_installs":71,"downloaded":129,"rating":28,"num_ratings":28,"last_updated":130,"tested_up_to":16,"requires_at_least":131,"requires_php":132,"tags":133,"homepage":135,"download_link":136,"security_score":11,"vuln_count":28,"unpatched_count":28,"last_vuln_date":38,"fetched_at":30},"klaviyo-for-gravity-forms","Integrate Klaviyo with Contact Form 7, Gravity Forms, WPForms and Elementor Forms","1.0.1","PluginsCafe","https:\u002F\u002Fprofiles.wordpress.org\u002Fpluginscafe\u002F","\u003Cp>The Klaviyo Integration plugin empowers you to easily add or subscribe users to your Klaviyo lists straight from your WordPress forms. With built-in support for multiple top-tier form builders, you can ensure your email marketing campaigns are automatically populated without any manual data entry.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Supported Form Builders:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Gravity Forms\u003Cbr \u002F>\n* Contact Form 7 (CF7)\u003Cbr \u002F>\n* WPForms\u003Cbr \u002F>\n* Elementor Forms\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Features:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Subscribe users to any of your Klaviyo lists upon form submission.\u003Cbr \u002F>\n* Map standard fields (Email, First Name, Last Name) directly to Klaviyo profiles.\u003Cbr \u002F>\n* Simple and intuitive settings directly inside your form builder.\u003Cbr \u002F>\n* Fully integrates with the official Klaviyo Lists API.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Important Notice:\u003C\u002Fstrong>\u003Cbr \u002F>\nTo use this plugin, you will need a valid Klaviyo API key. By using this plugin and Klaviyo’s services, you agree to Klaviyo’s Legal, Terms, & Policies available here: https:\u002F\u002Fwww.klaviyo.com\u002Flegal.\u003C\u002Fp>\n","Seamlessly connect your favorite WordPress form builders to Klaviyo and automatically subscribe users to your email and SMS lists.",1433,"2026-06-07T11:45:00.000Z","6.5","8.2",[20,21,22,23,134],"klaviyo","https:\u002F\u002Fpluginscafe.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fklaviyo-for-gravity-forms.1.0.1.zip",{"attackSurface":138,"codeSignals":221,"taintFlows":254,"riskAssessment":318,"analyzedAt":327},{"hooks":139,"ajaxHandlers":193,"restRoutes":202,"shortcodes":211,"cronEvents":216,"entryPointCount":219,"unprotectedCount":220},[140,146,150,155,159,164,167,172,176,180,184,188],{"type":141,"name":142,"callback":143,"file":144,"line":145},"action","rest_api_init","create_rest_api_login_user","blocks\\mailercloud-forms.php",149,{"type":141,"name":147,"callback":148,"file":144,"line":149},"init","mailercloud_forms_block_init",206,{"type":141,"name":151,"callback":152,"file":153,"line":154},"admin_menu","add_mailercloud_admin_menu","mailercloud.php",62,{"type":141,"name":156,"callback":157,"file":153,"line":158},"plugins_loaded","mailercloud_plugin_init",66,{"type":141,"name":160,"callback":161,"priority":162,"file":153,"line":163},"activated_plugin","mailercloud_activation_redirect",9,70,{"type":141,"name":147,"callback":165,"file":153,"line":166},"mailercloud_add_custom_shortcode",76,{"type":168,"name":169,"callback":170,"file":153,"line":171},"filter","cron_schedules","mailercloud_cron_extra_schedules",78,{"type":141,"name":173,"callback":174,"file":153,"line":175},"mailercloud_cron_every_five_minutes","sync_contact_every_five_minutes_event",79,{"type":141,"name":177,"callback":178,"priority":179,"file":153,"line":13},"user_register","mailercloud_registration_save",11,{"type":141,"name":181,"callback":182,"priority":71,"file":153,"line":183},"profile_update","mailercloud_updated_user_details",81,{"type":141,"name":185,"callback":186,"file":153,"line":187},"admin_enqueue_scripts","mailercloud_admin_enqueue",158,{"type":141,"name":189,"callback":190,"file":191,"line":192},"widgets_init","mailer_register_widget","widgets\\mailercloud_widget.php",24,[194,196,199,201],{"action":195,"nopriv":51,"callback":195,"hasNonce":51,"hasCapCheck":51,"file":153,"line":48},"mailercloud_create_new_property",{"action":195,"nopriv":197,"callback":195,"hasNonce":51,"hasCapCheck":51,"file":153,"line":198},true,90,{"action":200,"nopriv":51,"callback":200,"hasNonce":51,"hasCapCheck":51,"file":153,"line":87},"mailercloud_sync_contacts_now_ajax",{"action":200,"nopriv":197,"callback":200,"hasNonce":51,"hasCapCheck":51,"file":153,"line":11},[203],{"namespace":204,"route":205,"methods":206,"callback":208,"permissionCallback":209,"file":144,"line":210},"mailcloud\u002Fv1","\u002Fget-signup-forms",[207],"POST","mailcloud_rest_api_get_signup_forms","__return_true",157,[212],{"tag":213,"callback":214,"file":153,"line":215},"sibwp_form","create_dynamic_shortcode_signup_form",485,[217],{"hook":173,"callback":173,"file":153,"line":218},493,6,5,{"dangerousFunctions":222,"sqlUsage":223,"outputEscaping":225,"fileOperations":71,"externalRequests":220,"nonceChecks":52,"capabilityChecks":28,"bundledLibraries":253},[],{"prepared":28,"raw":28,"locations":224},[],{"escaped":226,"rawEcho":227,"locations":228},117,12,[229,232,234,237,239,241,243,245,246,248,250,251],{"file":153,"line":230,"context":231},329,"raw output",{"file":153,"line":233,"context":231},467,{"file":235,"line":236,"context":231},"templates\\mailercloud-subscriber-synchronisation.php",203,{"file":191,"line":238,"context":231},45,{"file":191,"line":240,"context":231},47,{"file":191,"line":242,"context":231},98,{"file":191,"line":244,"context":231},148,{"file":191,"line":145,"context":231},{"file":191,"line":247,"context":231},150,{"file":191,"line":249,"context":231},154,{"file":191,"line":249,"context":231},{"file":191,"line":252,"context":231},156,[],[255,271,284,301],{"entryPoint":256,"graph":257,"unsanitizedCount":14,"severity":41},"mailercloud_create_new_property (mailercloud.php:302)",{"nodes":258,"edges":269},[259,264],{"id":260,"type":261,"label":262,"file":153,"line":263},"n0","source","$_POST",314,{"id":265,"type":266,"label":267,"file":153,"line":230,"wp_function":268},"n1","sink","echo() [XSS]","echo",[270],{"from":260,"to":265,"sanitized":51},{"entryPoint":272,"graph":273,"unsanitizedCount":28,"severity":283},"create_mailercloud_settings_page (mailercloud.php:754)",{"nodes":274,"edges":281},[275,277],{"id":260,"type":261,"label":262,"file":153,"line":276},779,{"id":265,"type":266,"label":278,"file":153,"line":279,"wp_function":280},"update_option() [Settings Manipulation]",788,"update_option",[282],{"from":260,"to":265,"sanitized":197},"low",{"entryPoint":285,"graph":286,"unsanitizedCount":28,"severity":283},"create_mailercloud_synchronisation_settings_page (mailercloud.php:827)",{"nodes":287,"edges":298},[288,291,292,295],{"id":260,"type":261,"label":289,"file":153,"line":290},"$_POST['list_id']",997,{"id":265,"type":266,"label":278,"file":153,"line":290,"wp_function":280},{"id":293,"type":261,"label":262,"file":153,"line":294},"n2",996,{"id":296,"type":266,"label":278,"file":153,"line":297,"wp_function":280},"n3",998,[299,300],{"from":260,"to":265,"sanitized":197},{"from":293,"to":296,"sanitized":197},{"entryPoint":302,"graph":303,"unsanitizedCount":28,"severity":283},"\u003Cmailercloud> (mailercloud.php:0)",{"nodes":304,"edges":314},[305,307,308,309,310,312],{"id":260,"type":261,"label":306,"file":153,"line":263},"$_POST (x2)",{"id":265,"type":266,"label":267,"file":153,"line":230,"wp_function":268},{"id":293,"type":261,"label":306,"file":153,"line":276},{"id":296,"type":266,"label":278,"file":153,"line":279,"wp_function":280},{"id":311,"type":261,"label":289,"file":153,"line":290},"n4",{"id":313,"type":266,"label":278,"file":153,"line":290,"wp_function":280},"n5",[315,316,317],{"from":260,"to":265,"sanitized":197},{"from":293,"to":296,"sanitized":197},{"from":311,"to":313,"sanitized":197},{"summary":319,"deductions":320},"The plugin \"mailercloud-integrate-webforms-synchronize-contacts\" version 1.0.7 exhibits several concerning security weaknesses, primarily related to its unprotected entry points. While the plugin demonstrates good practices in avoiding dangerous functions and utilizing prepared statements for SQL queries, a significant portion of its attack surface lacks proper authentication and authorization checks. Specifically, 4 out of 4 AJAX handlers and 1 out of 1 REST API route are exposed without any form of permission validation, creating a substantial risk for unauthorized actions if these endpoints can be triggered by unauthenticated users.  The presence of 1 unsanitized path in the taint analysis, though not classified as critical or high severity, warrants attention as it could potentially lead to unexpected behavior or further vulnerabilities. The plugin's clean vulnerability history is a positive indicator of its development quality thus far, but it does not mitigate the immediate risks presented by the unprotected entry points.  In conclusion, while the plugin has strengths in secure coding practices for database interactions and output escaping, the extensive lack of authorization on its entry points is a significant security concern that elevates the overall risk profile.",[321,323,325],{"reason":322,"points":71},"AJAX handlers without auth checks",{"reason":324,"points":220},"REST API routes without permission callbacks",{"reason":326,"points":220},"Taint flow with unsanitized path","2026-03-16T20:45:20.211Z",{"wat":329,"direct":346},{"assetPaths":330,"generatorPatterns":337,"scriptPaths":338,"versionParams":339},[331,332,333,334,335,336],"\u002Fwp-content\u002Fplugins\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Fassets\u002Fcss\u002Fmailercloud-style.css","\u002Fwp-content\u002Fplugins\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Fassets\u002Fsweetalert\u002Fsweetalert2.min.css","\u002Fwp-content\u002Fplugins\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Fassets\u002Fjs\u002Fmailercloud-scripts.js","\u002Fwp-content\u002Fplugins\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Fassets\u002Fsweetalert\u002Fsweetalert2.min.js","\u002Fwp-content\u002Fplugins\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Fassets\u002Fjs\u002Fmailercloud-frontend.js","\u002Fwp-content\u002Fplugins\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Fassets\u002Fcss\u002Fmailercloud-frontend.css",[],[],[340,341,342,343,344,345],"\u002Fmailercloud-style.css?ver=","\u002Fsweetalert2.min.css?ver=","\u002Fmailercloud-scripts.js?ver=","\u002Fsweetalert2.min.js?ver=","\u002Fmailercloud-frontend.js?ver=","\u002Fmailercloud-frontend.css?ver=",{"cssClasses":347,"htmlComments":351,"htmlAttributes":352,"restEndpoints":354,"jsGlobals":357,"shortcodeOutput":360},[348,349,350],"mailercloud-settings-page","mailercloud-subscriber-synchronisation","mailercloud-signup-form-listing",[],[353],"mailercloud_api_key",[355,356],"\u002Fwp-json\u002Fmailercloud\u002Fv1\u002Fcreate_new_property","\u002Fwp-json\u002Fmailercloud\u002Fv1\u002Fsync_contacts_now_ajax",[358,359],"admAjax","ajax_object",[],{"error":197,"url":362,"statusCode":363,"statusMessage":364,"message":364},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":366,"versions":367},13,[368,373,380,387,394,400,408,416,424,432,440,448,455],{"version":6,"download_url":26,"svn_tag_url":369,"released_at":38,"has_diff":51,"diff_files_changed":370,"diff_lines":38,"trac_diff_url":371,"vulnerabilities":372,"is_current":197},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Ftags\u002F1.1.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.1.0&new_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.1.1",[],{"version":374,"download_url":375,"svn_tag_url":376,"released_at":38,"has_diff":51,"diff_files_changed":377,"diff_lines":38,"trac_diff_url":378,"vulnerabilities":379,"is_current":51},"1.1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmailercloud-integrate-webforms-synchronize-contacts.1.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Ftags\u002F1.1.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.10&new_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.1.0",[],{"version":381,"download_url":382,"svn_tag_url":383,"released_at":38,"has_diff":51,"diff_files_changed":384,"diff_lines":38,"trac_diff_url":385,"vulnerabilities":386,"is_current":51},"1.0.10","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmailercloud-integrate-webforms-synchronize-contacts.1.0.10.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Ftags\u002F1.0.10\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.9&new_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.10",[],{"version":388,"download_url":389,"svn_tag_url":390,"released_at":38,"has_diff":51,"diff_files_changed":391,"diff_lines":38,"trac_diff_url":392,"vulnerabilities":393,"is_current":51},"1.0.9","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmailercloud-integrate-webforms-synchronize-contacts.1.0.9.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Ftags\u002F1.0.9\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.8&new_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.9",[],{"version":40,"download_url":395,"svn_tag_url":396,"released_at":38,"has_diff":51,"diff_files_changed":397,"diff_lines":38,"trac_diff_url":398,"vulnerabilities":399,"is_current":51},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmailercloud-integrate-webforms-synchronize-contacts.1.0.8.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Ftags\u002F1.0.8\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.7&new_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.8",[],{"version":401,"download_url":402,"svn_tag_url":403,"released_at":38,"has_diff":51,"diff_files_changed":404,"diff_lines":38,"trac_diff_url":405,"vulnerabilities":406,"is_current":51},"1.0.7","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmailercloud-integrate-webforms-synchronize-contacts.1.0.7.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Ftags\u002F1.0.7\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.6&new_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.7",[407],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":409,"download_url":410,"svn_tag_url":411,"released_at":38,"has_diff":51,"diff_files_changed":412,"diff_lines":38,"trac_diff_url":413,"vulnerabilities":414,"is_current":51},"1.0.6","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmailercloud-integrate-webforms-synchronize-contacts.1.0.6.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Ftags\u002F1.0.6\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.5&new_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.6",[415],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":417,"download_url":418,"svn_tag_url":419,"released_at":38,"has_diff":51,"diff_files_changed":420,"diff_lines":38,"trac_diff_url":421,"vulnerabilities":422,"is_current":51},"1.0.5","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmailercloud-integrate-webforms-synchronize-contacts.1.0.5.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Ftags\u002F1.0.5\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.4&new_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.5",[423],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":425,"download_url":426,"svn_tag_url":427,"released_at":38,"has_diff":51,"diff_files_changed":428,"diff_lines":38,"trac_diff_url":429,"vulnerabilities":430,"is_current":51},"1.0.4","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmailercloud-integrate-webforms-synchronize-contacts.1.0.4.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Ftags\u002F1.0.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.3&new_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.4",[431],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":433,"download_url":434,"svn_tag_url":435,"released_at":38,"has_diff":51,"diff_files_changed":436,"diff_lines":38,"trac_diff_url":437,"vulnerabilities":438,"is_current":51},"1.0.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmailercloud-integrate-webforms-synchronize-contacts.1.0.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Ftags\u002F1.0.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.2&new_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.3",[439],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":441,"download_url":442,"svn_tag_url":443,"released_at":38,"has_diff":51,"diff_files_changed":444,"diff_lines":38,"trac_diff_url":445,"vulnerabilities":446,"is_current":51},"1.0.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmailercloud-integrate-webforms-synchronize-contacts.1.0.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Ftags\u002F1.0.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.1&new_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.2",[447],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":124,"download_url":449,"svn_tag_url":450,"released_at":38,"has_diff":51,"diff_files_changed":451,"diff_lines":38,"trac_diff_url":452,"vulnerabilities":453,"is_current":51},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmailercloud-integrate-webforms-synchronize-contacts.1.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Ftags\u002F1.0.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0&new_path=%2Fmailercloud-integrate-webforms-synchronize-contacts%2Ftags%2F1.0.1",[454],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40},{"version":456,"download_url":457,"svn_tag_url":458,"released_at":38,"has_diff":51,"diff_files_changed":459,"diff_lines":38,"trac_diff_url":38,"vulnerabilities":460,"is_current":51},"1.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmailercloud-integrate-webforms-synchronize-contacts.1.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fmailercloud-integrate-webforms-synchronize-contacts\u002Ftags\u002F1.0\u002F",[],[461],{"id":34,"url_slug":35,"title":36,"severity":41,"cvss_score":42,"vuln_type":44,"patched_in_version":40}]